[Dec 14, 2024] Latest CompTIA CS0-002 Exam Practice Test To Gain Brilliante Result [Q76-Q92]

Share

Latest [Dec 14, 2024] CompTIA CS0-002 Exam Practice Test To Gain Brilliante Result

Take a Leap Forward in Your Career by Earning CompTIA CS0-002

NEW QUESTION # 76
A vulnerability scan came back with critical findings for a Microsoft SharePoint server:

Which of the following actions should be taken?

  • A. Patch Microsoft Office on the server.
  • B. Remove Microsoft Office from the server.
  • C. Document the finding as an exception.
  • D. Install a newer version of Microsoft Office on the server.

Answer: A


NEW QUESTION # 77
An organization wants to move non-essential services into a cloud computing environment. Management has a cost focus and would like to achieve a recovery time objective of 12 hours. Which of the following cloud recovery strategies would work BEST to attain the desired outcome?

  • A. Configure the systems with a cold site at another cloud provider that can be used for failover.
  • B. Duplicate all services in another instance and load balance between the instances.
  • C. Set up a warm disaster recovery site with the same cloud provider in a different region
  • D. Establish a hot site with active replication to another region within the same cloud provider.

Answer: C

Explanation:
A hot site is always ready to take over the primary site's workload, so wouldn't it be more cost-effective in the long run? Additionally, a hot site would provide faster recovery times and better protection against data loss compared to a warm site.


NEW QUESTION # 78
Company A is m the process of merging with Company B As part of the merger, connectivity between the ERP systems must be established so portent financial information can be shared between the two entitles. Which of the following will establish a more automated approach to secure data transfers between the two entities?

  • A. Set up a PKI between Company A and Company B and Intermediate shared certificates between the two entities
  • B. Create static NATs on each entity's firewalls that map lo the ERP systems and use native ERP authentication to allow access.
  • C. Set up an FTP server that both companies can access and export the required financial data to a folder.
  • D. Set up a VPN between Company A and Company B. granting access only lo the ERPs within the connection

Answer: D


NEW QUESTION # 79
A security analyst is running a routine vulnerability scan against a web farm. The farm consists of a single server acting as a load-balancing reverse proxy and offloads cryptographic processes to the backend servers. The backend servers consist of four servers that process the inquiries for the front end.

A web service SSL query of each server responds with the same output:
Connected (0x000003)
depth=0 /0=farm.company.com/CN=farm.company.com/OU=Domain Control Validated Which of the following results BEST addresses these findings?

  • A. Advise the application development team that the SSL certificates on the backend servers should be revoked and reissued to match their hostnames
  • B. Notify the application development team of the findings and advise management of the results
  • C. Require that the application development team renews the farm certificate and includes a wildcard for the `local' domain in the certificate SAN field
  • D. Create an exception in the vulnerability scanner, as the results and false positives and can be ignored safely

Answer: D


NEW QUESTION # 80
Which of me following BEST articulates the benefit of leveraging SCAP in an organization's cybersecurity analysis toolset?

  • A. It provides validation of suspected system vulnerabilities through workflow orchestration
  • B. It establishes a continuous integration environment for software development operations
  • C. It automatically performs remedial configuration changes lo enterprise security services
  • D. It enables standard checklist and vulnerability analysis expressions for automaton

Answer: D


NEW QUESTION # 81
Malware is suspected on a server in the environment.
The analyst is provided with the output of commands from servers in the environment and needs to review all output files in order to determine which process running on one of the servers may be malware.
INSTRUCTIONS
Servers 1, 2, and 4 are clickable. Select the Server and the process that host the malware.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.



Answer:

Explanation:

Explanation
Server 4 192.168.50.6 Windows, svchost.exe


NEW QUESTION # 82
An organization has the following policy statements:
* AlI emails entering or leaving the organization will be subject to inspection for malware, policy violations, and unauthorized coolant.
* AM network activity will be logged and monitored.
* Confidential data will be tagged and tracked
* Confidential data must never be transmitted in an unencrypted form.
* Confidential data must never be stored on an unencrypted mobile device.
Which of the following is the organization enforcing?

  • A. Acceptable use policy
  • B. Encryption policy
  • C. Data management, policy
  • D. Data privacy policy

Answer: D


NEW QUESTION # 83
You are a cybersecurity analyst tasked with interpreting scan data from Company A's servers. You must verify the requirements are being met for all of the servers and recommend changes if you find they are not.
The company's hardening guidelines indicate the following:
* TLS 1.2 is the only version of TLS running.
* Apache 2.4.18 or greater should be used.
* Only default ports should be used.
INSTRUCTIONS
Using the supplied data, record the status of compliance with the company's guidelines for each server.
The question contains two parts: make sure you complete Part 1 and Part 2. Make recommendations for issues based ONLY on the hardening guidelines provided.




Answer:

Explanation:
Part 1 answer:
Check on the following:
AppServ1 is only using TLS.1.2
AppServ4 is only using TLS.1.2
AppServ1 is using Apache 2.4.18 or greater
AppServ3 is using Apache 2.4.18 or greater
AppServ4 is using Apache 2.4.18 or greater
Part 2 answer:
Recommendation:
Recommendation is to disable TLS v1.1 on AppServ2 and AppServ3. Also upgrade AppServ2 Apache to version 2.4.48 from its current version of 2.3.48


NEW QUESTION # 84
After completing a vulnerability scan, the following output was noted:

Which of the following vulnerabilities has been identified?

  • A. VPN tunnel vulnerability.
  • B. Web application cryptography vulnerability.
  • C. PKI transfer vulnerability.
  • D. Active Directory encryption vulnerability.

Answer: B


NEW QUESTION # 85
While planning segmentation for an ICS environment, a security engineer determines IT resources will need access to devices within the ICS environment without compromising security.
To provide the MOST secure access model in this scenario, the jumpbox should be.

  • A. placed in an isolated network segment, authenticated on the IT side, and forwarded into the ICS network.
  • B. placed on the ICS network with a static firewall rule that allows IT network resources to authenticate.
  • C. bridged between the IT and operational technology networks to allow authenticated access.
  • D. placed on the IT side of the network, authenticated, and tunneled into the ICS environment.

Answer: A


NEW QUESTION # 86
A malicious hacker wants to gather guest credentials on a hotel 802.11 network. Which of the following tools is the malicious hacker going to use to gain access to information found on the hotel network?

  • A. tcpdump
  • B. Nikto
  • C. Nessus
  • D. Aircrak-ng

Answer: B


NEW QUESTION # 87
A security analyst recently used Arachni to perform a vulnerability assessment of a newly developed web application. The analyst is concerned about the following output:

Which of the following is the MOST likely reason for this vulnerability?

  • A. The developer did not implement default protections in the web application build.
  • B. The developer did not set proper cross-site scripting protections in the header.
  • C. The developer did not set proper cross-site request forgery protections.
  • D. The developer set input validation protection on the specific field of search.aspx.

Answer: D


NEW QUESTION # 88
The security team at a large corporation is helping the payment-processing team to prepare for a regulatory compliance audit and meet the following objectives:
* Reduce the number of potential findings by the auditors.
* Limit the scope of the audit to only devices used by the payment-processing team for activities directly impacted by the regulations.
* Prevent the external-facing web infrastructure used by other teams from coming into scope.
* Limit the amount of exposure the company will face if the systems used by the payment-processing team are compromised.
Which of the following would be the MOST effective way for the security team to meet these objectives?

  • A. Deploy patches to all servers and workstations across the entire organization.
  • B. Limit the permissions to prevent other employees from accessing data owned by the business unit.
  • C. Segment the servers and systems used by the business unit from the rest of the network.
  • D. Implement full-disk encryption on the laptops used by employees of the payment-processing team.

Answer: C


NEW QUESTION # 89
A remote code-execution vulnerability was discovered in the RDP for the servers running a key-hosted application. While there is no automated check for this vulnerability from the vulnerability assessment vendor, the in-house technicians were able to evaluate manually whether this vulnerability was present through the use of custom scripts. This evaluation determined that all the hosts are vulnerable. A technician then tested the patch for this vulnerability and found that it can cause stability issues in the key-hosted application. The application is accessed through RDP to a jump host that does not run the application directly. To mitigate this vulnerability, the security operations team needs to provide remediation steps that will mitigate the vulnerability temporarily until the compatibility issues with the patch are resolved. Which of the following will BEST allow systems to continue to operate and mitigate the vulnerability in the short term?

  • A. Implement IPSec rules on the jump host server through a GPO that limits RDP access from only the other application servers. Do not patch the jump host. Since it does not run the application natively, it is at less risk of being compromised. Patch the application servers to secure them.
  • B. Implement IPSec rules on the application servers through a GPO that limits RDP access from only the jump host. Patch the jump host. Since it does not run the application natively, it will not affect the software's operation and functionality. Do not patch the application servers until the compatibility issue is resolved.
  • C. Implement firewall rules on the application servers through a GPO that limits RDP access to only other application servers. Manually check the jump host to see if it has been compromised. Patch the application servers to secure them.
  • D. Implement IPSec rules on the application servers through a GPO that limits RDP access to only other application servers. Do not patch the jump host. Since it does not run the application natively, it is at less risk of being compromised. Patch the application servers to secure them.

Answer: B


NEW QUESTION # 90
Clients are unable to access a company's API to obtain pricing data. An analyst discovers sources other than clients are scraping the API for data, which is causing the servers to exceed available resources. Which of the following would be BEST to protect the availability of the APIs?

  • A. Web application firewall
  • B. Certificate-based authentication
  • C. Virtual private network
  • D. IP whitelisting

Answer: D


NEW QUESTION # 91
A forensic analyst took an image of a workstation that was involved in an incident To BEST ensure the image is not tampered with me analyst should use:

  • A. chain of custody.
  • B. backup tapes
  • C. a legal hold
  • D. hashing

Answer: D


NEW QUESTION # 92
......

Authentic Best resources for CS0-002 Online Practice Exam: https://www.test4sure.com/CS0-002-pass4sure-vce.html

Updates Up to 365 days On Developing CS0-002 Braindumps: https://drive.google.com/open?id=18eCZOeXLs_nssm5dlTqiQN8iTasCYMUs